HashiCorp security advisory (AV26-910)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial Number: AV26-910Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1.21.18 21.0 Prior to 1.21.18 9.0 Prior to 1.21.18 consul-template Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh Security - HashiCorp Discuss

This version

Version
1 of 1
Recorded
September 20, 2026 19:55
Change
Initial
Content hash
054a3ce8b80ee897e65aca25382fa5ab
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.